• dgdft@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    edit-2
    13 hours ago

    That would be fair if this was something people had to enable consciously.

    In context, I think it’s pretty victim-blamey to assume people should know 1) the default services running on their router are insecure and 2) that the web config interface is exposed publicly OOTB, instead of only to their LAN.

    This is a huge fuckup by Mikrotik, not the users.

    E: Checking the docs, I think I was wrong that it’s enabled publicly OOTB. I tried hitting my own router earlier from public IP and it looked like it was getting through, but maybe the traffic was getting bridged automatically.

    • moonshine69@lemmy.nz
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 hours ago

      Idk, microtiks are pretty prosumer, not at all plug and play. Configuring one is a complex task already, people that have that level of skill should absolutely know not to go doing silly things…

    • Thorry@feddit.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      12 hours ago

      Yeah no, the same was said about the previous vulnerability in the SSH server. News stories just assume when people run an unpatched version they are vulnerable from attacks from the internet and run with those numbers. It makes for a better story, but it isn’t the whole truth. OOTB these kinds of things aren’t exposed to the outside world and exposing them isn’t trivial.

      People should still patch and these vulnerabilities aren’t a good thing obviously, but the news stories have been pretty sensational for something that probably won’t impact a lot of users.

      • dgdft@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        12 hours ago

        Wasn’t going off the article: I saw the SSH stuff last month and had double-checked I had all remote-access off on my config.

        Then when I saw the latest story this morning, I ran an nmap that showed webfig was still exposed on my pub IP. Probably just due to some automatic bridging behavior that bit me, but I’ll have to confirm later.

        • Thorry@feddit.org
          link
          fedilink
          English
          arrow-up
          2
          ·
          12 hours ago

          I know, the articles just annoy me. I use a lot of Mikrotik stuff and it’s great. Then you get these MILLIONS OF USERS VULNERABLE!!! bullshit stories and it pisses me off.